{"id":"CVE-2026-104059","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-104059","summary":"Lektor 3.3.14 CSRF via Admin API Endpoints","details":"Lektor 3.3.14 and 3.4.0b15 contains a cross-site request forgery vulnerability in the admin API blueprint that allows unauthenticated attackers to perform state-changing actions by sending cross-origin requests without CSRF tokens, Origin/Referer validation, CORS configuration, or Host allowlisting. Attackers can exploit the newattachment, deleterecord, build, clean, and publish endpoints from a malicious web page to write arbitrary files, delete pages, wipe build output, trigger deployment publication, and via DNS rebinding reach read endpoints to disclose data.","published":"2026-10-01T18:17:39.168Z","modified":"2026-10-02T03:47:26.059395287Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"ARTICLE","url":"https://gist.github.com/mansurmavlankulov/c7683e3204e84892e442b0196585d5bb"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/104xxx/CVE-2026-104059.json"},{"type":"PACKAGE","url":"https://github.com/lektor/lektor"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104059"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/lektor-csrf-via-admin-api-endpoints"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-10-02T03:47:26.059395287Z"}}